Gooood Morning 🙂
I need some advice, we have several sources of Information about our Company assets, i know not ideal but better then dont know any.
So i wrote a script thats collects everything from these Asset sources and writes the Info to a big KV Store. (1.5GB) on the Splunk-ES SH.
The script does that every 6h.
No i want to add these Info to the Splunk ES Asset- und Identitäts-Management.
How do i aliase a kvstore field name so its CIM compliance with the required fieldnames as stated here. https://docs.splunk.com/ ?
I thought about fieldaliases in a props.conf as per normal datasources.
But im not sure to use the collection name as a source in the stanza?
[source::ipam_assets_collection]
FIELDALIAS-asset_ip = Address AS ip